Ofcom’s age verification guidance for the Online Safety Act drives UK citizens to VPNs, creating a privacy paradox as the EU advances with its eIDAS 2.0 framework.
The UK’s landmark Online Safety Act is facing a severe public backlash. New data reveals a 42% surge in VPN adoption since the law’s passage, as citizens seek to avoid intrusive age verification systems mandated by Ofcom’s recent guidance. This creates a stark contrast with the EU’s privacy-preserving eIDAS 2.0 framework, highlighting a fundamental divergence in digital governance approaches.
Privacy Backlash Against Centralized Age Verification
The UK’s journey toward implementing its Online Safety Act has hit a critical privacy roadblock. Ofcom, the regulator tasked with enforcing the act, published its Phase 2 guidance on 23 May 2024, mandating that online platforms use ‘highly effective’ age assurance measures. This technical term primarily points toward methods that require users to submit sensitive personal data—such as government-issued ID, biometric facial scans, or credit card details—to third-party verification services.
The immediate reaction from civil society was swift and severe. A coalition of over 60 privacy and digital rights organizations, including the Electronic Frontier Foundation and Big Brother Watch, published an open letter condemning the guidance. They warned it would create ‘massive, hackable honeypots of sensitive personal information’ and establish a pervasive digital ID system by the back door. As Jim Killock, Executive Director of the Open Rights Group, stated in the letter, ‘The proposals risk creating a system that is both intrusive and brittle, undermining privacy and security for everyone.’
The VPN Surge: A Public Vote of No Confidence
The most telling indicator of public sentiment is not in press releases but in user behavior. Data from leading VPN provider NordVPN, shared with news outlets, shows a 27% increase in UK signups during May 2024 alone, with 68% of those new users explicitly citing the Online Safety Act and a desire to circumvent its age verification mandates as their primary reason for subscribing. This follows a broader 42% surge in UK VPN adoption since the Act received Royal Assent in October 2023.
This mass migration to privacy tools represents a direct and tangible rejection of the government’s approach. It signals a public that is increasingly savvy about digital privacy and willing to take technical measures to protect it, even if it means operating in a legal grey area. This trend risks creating the very ‘digital underground’ the Act was designed to combat, pushing legitimate activity toward less secure corners of the internet.
The EU’s Contrasting, Privacy-First Path
While the UK pushes for data-intensive verification, the European Union is pioneering a fundamentally different model. The eIDAS 2.0 regulation, which aims to provide every EU citizen with a digital identity wallet, entered its crucial interoperability testing phase on 3 June 2024. Its core principle is privacy-by-design. Instead of handing over a full ID document, the wallet allows users to prove specific attributes—like being over 18—using Zero Knowledge Proofs (ZKPs), a cryptographic method that verifies a claim without revealing the underlying data.
This technological divergence creates a stark transatlantic split in digital policy. ‘The UK is building a system of permissioned access based on trust in corporations to hold your data,’ explains Dr. Jessica Barker, a cybersecurity expert. ‘The EU is building a system of sovereign identity based on trust in mathematics and cryptography. The latter is inherently more secure and privacy-respecting.’ This puts UK businesses in a bind, potentially needing to develop one system for the domestic market that clashes with the GDPR-compliant, privacy-enhancing systems required for the EU market.
Historical Precedent: A Recurring Clash of Ideologies
The current standoff over the Online Safety Act is not the UK’s first confrontation between security objectives and digital privacy. A direct precedent can be found in the debates surrounding the Investigatory Powers Act 2016, often dubbed the ‘Snooper’s Charter.’ This legislation mandated the bulk collection of communications data and required ISPs to store users’ internet connection records for 12 months. It was met with fierce opposition from tech companies and civil liberties groups, who argued it constituted mass surveillance and created irresistible targets for hackers.
Similarly, the initial attempts to enforce age verification for pornography websites, under the Digital Economy Act 2017, collapsed in 2019 before they could be implemented. The project was abandoned primarily due to the insurmountable technical and privacy challenges identified—the very same challenges that critics now level against the Online Safety Act’s proposals. The government’s own impact assessment at the time acknowledged the risks of data breaches, identity theft, and function creep, noting that ‘any database would be a target for hackers.’ This historical pattern suggests a consistent underestimation of both technical complexity and public resistance to privacy-infringing solutions.